Use cases · Argus Pentest

Keep scan data on your own infrastructure

Keep scan data on your own infrastructure with Argus Pentest: a practical, on-prem approach built for Azerbaijani teams.

Enterprise-Grade Authenticated Security Scanning

Argus Pentest delivers authenticated dynamic security scanning specifically engineered for enterprise web applications and their associated APIs. As one of the three core engines of the Argus self-hosted AI testing platform, it leverages a shared runtime, model layer, credential store, and cost ledger alongside the QA and AI engines. By operating entirely on your own infrastructure, the platform ensures that all sensitive scan data, credentials, and security reports remain within your perimeter, eliminating the risks associated with external SaaS dependencies. The primary differentiator of Argus Pentest is its ability to perform deep authenticated scanning. Rather than stopping at the login page, the system utilizes a scripted login process via an encrypted credential store to acquire session cookies and bearer tokens. This allows the scanner to operate as a legitimate logged-in user, discovering endpoints during the login and crawl phases to seed a synthesized API specification. This comprehensive approach ensures that the scan reaches the authenticated surface of the application, providing a realistic assessment of the security posture of your internal business logic.

Capabilities

Advantages of Self-Hosted Security Testing

Full data sovereignty by keeping all scan data and reports on your own infrastructure

Deep visibility into authenticated surfaces through scripted login and session token acquisition

Strict risk mitigation via an explicit allow-list that requires targets to be added deliberately

Modular flexibility using an open-source engine driven by a CLI contract for easy upgrades

Unified credential management shared across the platform's QA and AI testing engines

Accurate triage and payload generation powered by a dedicated text-based AI model

Core Capabilities

Authenticated Scanning

Uses a scripted login via an encrypted credential store to obtain session cookies and bearer tokens, operating as a real logged-in user.

Synthesized API Mapping

Endpoints discovered during login and crawling seed a synthesized API spec to ensure the scan reaches the authenticated surface.

AI-Driven Payloads

Utilizes a model specifically for payload generation and finding triage, operating on a text-in, text-out basis.

Strict Target Control

Scans run exclusively against an explicit allow-list of approved targets to prevent unauthorized scanning.

Flexible Reporting

Security findings are categorized by severity and delivered via HTML and JSON reports.

The Scanning Process

1Define an explicit allow-list of approved targets for scanning.
2Execute a scripted login using the encrypted credential store to acquire session tokens.
3Crawl the application to synthesize an API specification of the authenticated surface.
4Generate and deploy security payloads using the integrated AI model.
5Triage findings and export results via HTML or JSON reports.

Frequently Asked Questions

Where is the scan data stored?

All scan data, credentials, and reports stay on your own infrastructure, as the platform is self-hosted with no external SaaS dependency.

How does the scanner handle authentication?

It uses the QA engine's encrypted credential store to perform a scripted login, allowing it to scan the internal authenticated surface rather than stopping at the login page.

What happens if the scanner cannot authenticate?

Following the platform's honest-failure rule, a scanner that cannot authenticate is treated as an environment failure rather than a security finding.

Can the scanning engine be changed or updated?

Yes, the platform uses an open-source engine driven through a CLI contract, meaning it can be upgraded or replaced without modifying the platform.

How is AI utilized within the scanning process?

The AI model is used exclusively for payload generation and finding triage on a text-in, text-out basis; it does not utilize vision capabilities.

Ready to secure your infrastructure?

Deploy Argus Pentest on your own servers and start authenticated security scanning today.

Request a demo